← Course Home
Okta Certified Administrator · Part I

User Lifecycle Management

29% of the exam — the second-largest domain.

User Lifecycle Management

Module 2: Provisioning

4 sub-topics · this deck covers sub-topic 4 of 4 — the last one in this module

↑ Module 2 Overview

The Exam Bullet

"Demonstrate knowledge of how Group Push can push Okta groups to provisioning-enabled third-party apps"

Module 1 covered why Group Push matters. This is the deep dive on how it actually works — the mechanics an exam question will actually probe.

The Two Push Methods

By name — an admin manually selects specific groups to push.

By rule — multiple groups are pushed automatically based on matching criteria in group names or descriptions. Unavailable for Active Directory.

The Gotcha — Hard Limitations

Pushed groups can't simultaneously be used for app assignments.
Group Push doesn't create groups in Okta — they must already exist.
Okta only reconciles membership once Group Push is configured, removing any target-app members not present in the linked Okta group.

That last point matters: turning on Group Push for an existing app group can silently remove members who were only ever added on the app's side.

Group Linking — Create vs. Link

Create Group — generates a brand-new group in the target app and links it.

Link Group — connects an Okta group to an existing app group instead.

Once linked, the app-side group no longer appears under Directory > Groups. Admins can optionally auto-rename the app group to match Okta's name, and should run "Refresh App Groups" before linking to pick up any recent changes made directly in the app.

The Gotcha — Office 365 / Entra ID

For Microsoft Entra ID groups specifically: you can mark a group as role-assignable during creation — but you cannot change that setting afterward. Get it right the first time.

The Exam Angle

Watch for scenario questions built around these traps:

→ "A group needs to be pushed to Active Directory using rule-based matching." = not supported — AD only allows push by name.

→ "After enabling Group Push, some app-side members disappeared." = expected — Okta reconciles membership and removes anyone not in the linked Okta group.

→ "A pushed group also needs to be used for direct app assignment." = not possible — mutually exclusive.

One Line To Remember

Push by name (manual) or by rule (not for AD). Pushed groups can't double as app-assignment groups, must already exist in Okta, and get reconciled — meaning app-side-only members get removed. Group Linking = Create Group or Link Group; linked app groups vanish from Directory > Groups. Entra ID role-assignable status is set once, at creation, permanently.

Sources: help.okta.com — usgp-about-group-push.htm · usgp-configure-enhanced-group-push.htm

✓ Module 2: Provisioning — complete (4 of 4 sub-topics)